# LDAP configuration in 7+

**URL:** <https://discuss.elastic.co/t/ldap-configuration-in-7/185002>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 10, 2019, 2:12pm UTC](https://discuss.elastic.co/t/ldap-configuration-in-7/185002 "2019-06-10T14:12:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JamesNotJamez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesnotjamez/32/45736_2.png) [@JamesNotJamez](https://discuss.elastic.co/u/JamesNotJamez)\
**Post date:** [June 10, 2019, 2:12pm UTC](https://discuss.elastic.co/t/ldap-configuration-in-7/185002/1 "2019-06-10T14:12:02Z")

</div>

Hi,

In the breaking changes for Elasticsearch 7.0 it says to make this change to the LDAP config, [https://www.elastic.co/guide/en/elasticsearch/reference/current/breaking-changes-7.0.html#include-realm-type-in-setting](https://www.elastic.co/guide/en/elasticsearch/reference/current/breaking-changes-7.0.html#include-realm-type-in-setting)

However when looking at the documentation for 7.1 it is still using the old configuration, [https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-ldap-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-ldap-realm.html)

Could you clarify which is correct, or if I'm misinterpreting somewhere.

In any case, when trying to create a new cluster, using a user settings yaml that works in 6.7.2, I am unable to get it working if I leave the settings the same or make changes according to the breaking changes. Are there any other changes I need to be aware of that may be breaking it? Can send the configuration if this helps.

Also to note this is running on ECE 2.2.2 if this makes a difference.

Many thanks,

James

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [June 11, 2019, 12:21am UTC](https://discuss.elastic.co/t/ldap-configuration-in-7/185002/2 "2019-06-11T00:21:15Z")

</div>

Hi @JamesNotJamez,

I think the documentation looks good to me.  
The confusion may be because in the breaking documentation we specify the `ldap.ldap1` and in the ldap documentation, it is different. Both are valid YAML representation.

```auto
xpack.security.authc.realms:
  ldap.ldap1:
    order: 1
    url: "ldaps://ldap.example.com/"

```

and

```auto
xpack:
  security:
    authc:
      realms:
        ldap:
          ldap1:
            order: 1
            url: "ldaps://ldap.example.com/"

```

I think it would be good if you could upload the config file and there is an error message while parsing the file that you are using, so we can take a look at it?

Thanks and Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![JamesNotJamez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesnotjamez/32/45736_2.png) [@JamesNotJamez](https://discuss.elastic.co/u/JamesNotJamez)\
**Post date:** [June 11, 2019, 8:35am UTC](https://discuss.elastic.co/t/ldap-configuration-in-7/185002/3 "2019-06-11T08:35:51Z")

</div>

> [@Yogesh\_Gaikwad](#):
>
> Yogesh

Hi Yogesh,

I had another play around with it and have got it working now, think it was my misunderstanding of the YAML that was the issue 🤦‍♂️

Many thanks,  
James

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 8:35am UTC](https://discuss.elastic.co/t/ldap-configuration-in-7/185002/4 "2019-07-09T08:35:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
